CVE-2023-3575: Quiz And Survey Master < 8.1.11 - Contributor+ Stored XSS
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3575?
CVE-2023-3575 is a vulnerability in the Quiz And Survey Master WordPress plugin before version 8.1.11 that allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
What is the severity of CVE-2023-3575?
The severity of CVE-2023-3575 is medium with a CVSS score of 5.4.
How does CVE-2023-3575 affect the Quiz And Survey Master plugin?
CVE-2023-3575 affects the Quiz And Survey Master plugin before version 8.1.11 by not properly sanitizing and escaping question titles, which enables Stored Cross-Site Scripting attacks.
How can I fix CVE-2023-3575 in the Quiz And Survey Master plugin?
To fix CVE-2023-3575 in the Quiz And Survey Master plugin, update it to version 8.1.11 or later.
Where can I find more information about CVE-2023-3575?
More information about CVE-2023-3575 can be found at the following reference: https://wpscan.com/vulnerability/6f884688-2c0d-4844-bd31-ef7085edf112.